Privacy Policy

This Privacy Policy explains how Thrishula LLP ("Thrishula", "we", "us") collects, uses, discloses and safeguards information when you visit trishula.services or engage us for professional services.

Last updated: 1 January 2026

1. Who we are

Thrishula LLP is a limited liability partnership registered in India (LLPIN AAA-0000) with its registered office at Registered Office Address, Chennai, Tamil Nadu 600001. We act as the data fiduciary for the personal data described in this policy.

2. Information we collect

We collect only the information necessary to deliver the services you have engaged us for:

  • Identity and contact data — name, email address, phone number, postal address and designation.
  • Business and statutory data — entity name, PAN, GSTIN, LLPIN or CIN, incorporation documents, director and partner details, and financial statements you share with us.
  • Engagement data — quotations issued, invoices raised, payments received, filing status and correspondence relating to your matter.
  • Account data — login email and a securely hashed password if you are issued dashboard access.
  • Technical data — IP address, browser type, device information and pages visited, collected automatically when you use the website.

We do not knowingly collect information from persons under 18 years of age, and we do not collect sensitive personal data beyond what a statutory filing specifically requires.

3. How we use your information

  • To prepare quotations, deliver the professional services you engage us for, and make filings with the MCA, GSTN, Income Tax Department and other authorities on your behalf.
  • To raise invoices, collect payments and issue receipts and GST invoices.
  • To communicate about the status of your engagement, statutory due dates and notices received.
  • To maintain books, records and working papers as required by applicable law and professional standards.
  • To secure, operate and improve the website and client dashboard, and to detect and prevent fraud or misuse.
  • To comply with legal obligations, including responding to lawful requests from regulatory or judicial authorities.

We do not sell your personal data, and we do not use your business or financial information for advertising or profiling.

4. Legal basis for processing

We process personal data on the basis of your consent, the performance of our engagement contract with you, our legitimate interest in operating and securing our services, and compliance with legal obligations under Indian law.

5. Sharing and disclosure

We share information only in the following circumstances:

  • With government and regulatory authorities, where a filing, return or response requires it.
  • With service providers who support our operations — payment gateways, cloud hosting, email delivery and accounting software — under confidentiality obligations and only to the extent needed.
  • With professional advisors such as auditors and legal counsel, where necessary.
  • Where disclosure is required by law, court order, or to protect our rights, safety or property.
  • With your explicit instruction or consent.

Payment card and bank details are captured directly by our payment gateway partner on its own PCI-DSS compliant systems. We do not store complete card numbers, CVV or net banking credentials.

6. Data retention

Engagement records, invoices and statutory working papers are retained for at least eight years, or such longer period as required under the Companies Act 2013, the Income-tax Act 1961, the GST legislation and applicable professional standards. Website analytics and technical logs are retained for a shorter period. When information is no longer required, it is securely deleted or anonymised.

7. Security

We apply reasonable security practices consistent with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 — including encrypted transport (HTTPS), hashed passwords, role-based access control on the client dashboard, and access limited to personnel who need it. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Cookies

The website uses strictly necessary cookies to maintain your login session and to keep the site secure. We do not use third-party advertising cookies. You may block or delete cookies through your browser settings, although the client dashboard will not function without session cookies.

9. Your rights

Subject to applicable law, you may:

  • Request access to the personal data we hold about you.
  • Request correction of inaccurate or incomplete data.
  • Request erasure of data that we are not required by law to retain.
  • Withdraw consent to processing, where processing is based on consent.
  • Nominate another individual to exercise your rights in the event of death or incapacity.
  • Raise a grievance about how your data has been handled.

To exercise any of these rights, write to support@trishula.services. We will verify your identity and respond within 30 days.

10. Grievance officer

Complaints regarding this policy or the handling of your data may be sent to the Grievance Officer at support@trishula.services (subject: “Grievance”) or by post to our registered office. Complaints are acknowledged within 48 hours and resolved within 30 days.

11. Changes to this policy

We may update this Privacy Policy to reflect changes in law or our practices. The revised version will be posted on this page with an updated date. Continued use of the website or our services after an update constitutes acceptance of the revised policy.